CVE-2025-49581 | xwiki-platform up to 11.x/12.6/16.4.6/16.10.2 code injection (GHSA-9875-cw22-f7cx / EUVD-2025-18284)
A vulnerability classified as critical has been found in xwiki-platform up to 11.x/12.6/16.4.6/16.10.2. Affected is an unknown function. The manipulation leads to code injection.
This vulnerability is traded as CVE-2025-49581. It is possible to launch the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.